Security Advisory

CVE-2026-82125

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-16 06:00:12
Last updated 2026-09-17 12:38:24
Assigner WPScan
CVSS score 5.3
State PUBLISHED

Description

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, allowing unauthenticated users to read the content of comments still awaiting moderation or marked as spam.